Changing the labels on training examples to cause misclassification: - Flip "spam" labels to "not spam" for specific patterns - Flip "malicious" to "benign" for specific malware signatures